Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2018-4013

Description

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.

POC

Reference

- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0684

Github

- https://github.com/0xT11/CVE-POC

- https://github.com/DoubleMice/cve-2018-4013

- https://github.com/developer3000S/PoC-in-GitHub

- https://github.com/hectorgie/PoC-in-GitHub

- https://github.com/invictus1306/functrace

- https://github.com/q40603/Continuous-Invivo-Fuzz

- https://github.com/r3dxpl0it/RTSPServer-Code-Execution-Vulnerability